[Oisf-users] nfqueue or af_packet for suricata ips

C. L. Martinez carlopmart at gmail.com
Tue Mar 26 09:03:07 UTC 2013


Hi all,

 Next month, I will setup my first suricata IPS to monitor a 1 GB
network. AFAIK this can be accomplished using af_packet or nfqueue in
linux platforms. But, what is the best option for production systems??
(host will be CentOS 6.4 x86_64).

 I see the following post from Eric:
https://home.regit.org/2012/12/af-packet-oops/, and I don't know if
af_packet is the best option to use under this CentOS host.

Thanks.


More information about the Oisf-users mailing list